Original Release Date: 3/4/2021
Ten vulnerabilities have been discovered in SaltStack, seven of which are considered high severity. Successful exploitation of these vulnerabilities may result in remote code execution, shell injection, and access to sensitive information via a man-in-the-middle attack. One of the flaws, CVE-2020-28243, affects SaltStack minions and may also allow local privilege escalation. These vulnerabilities impact versions of Salt prior to 3002.5. The Salt Project has released a security update addressing these vulnerabilities.
The NJCCIC recommends users of affected versions update to the latest security release after appropriate testing. Additionally, older versions of Salt may need to be updated prior to applying an available patch.